StackRadar

CVE-2026-55858

Medium

Advisory

Published 28 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.003
28th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
158
of 17,781 indexed, latest versions
Container images
75
deployed by those charts
Fix available
1 of 1
affected package

org.mariadb.jdbc:mariadb-java-client has Inappropriate Encoding for Output Context

Carried by container images the latest versions of 158 of 17,781 indexed charts deploy, on 75 images.

Affected packageAffected versionsFixed inImages
mariadb-java-clientmaven1.7.4, 2.2.5, 2.3.0, 2.5.1+24 more2.7.14, 3.3.5, 3.4.3, 3.5.975
OSV records
GHSA-xvr9-35cr-46v9

Charts affected

158 by stars
ChartLatestAffected imagesRadar Score
metabasepmint932.27.61 of 1See more

metabase pmint93 2.27.6

1 of the 1 container images this version deploys carry CVE-2026-55858.

Container imageDigestPackageFixed in
metabase/metabase:v0.61.1.x9491ed11c901
mariadb-java-client@2.7.10
2.7.14

Open the chart page →

1,639
keycloakcodecentricVerified publisher18.10.01 of 3See more

keycloak codecentric 18.10.0

1 of the 3 container images this version deploys carry CVE-2026-55858.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
mariadb-java-client@2.5.4
2.7.14

Open the chart page →

7,713
trinotrino1.42.21 of 1See more

trino trino 1.42.2

1 of the 1 container images this version deploys carry CVE-2026-55858.

Container imageDigestPackageFixed in
trinodb/trino:4801565e8cac299
mariadb-java-client@3.3.4
3.3.5

Open the chart page →

1,309
zipkincarlosjgp0.2.01 of 2See more

zipkin carlosjgp 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-55858.

Container imageDigestPackageFixed in
openzipkin/zipkin:2.21.060c3970df479
mariadb-java-client@2.6.0
2.7.14

Open the chart page →

3,229
apim3graviteeioVerified publisher4.12.192 of 4See more

apim3 graviteeio 4.12.19

2 of the 4 container images this version deploys carry CVE-2026-55858.

Container imageDigestPackageFixed in
graviteeio/apim-gateway:4.12.19-debian05fd67a93056
mariadb-java-client@3.5.6
3.5.9
graviteeio/apim-management-api:4.12.19-debian27374522cd04
mariadb-java-client@3.5.6
3.5.9

Open the chart page →

4,806
cloudbeaveravistoVerified publisher1.1.71 of 1See more

cloudbeaver avisto 1.1.7

1 of the 1 container images this version deploys carry CVE-2026-55858.

Container imageDigestPackageFixed in
dbeaver/cloudbeaver:26.1.287ab86d00f8c
mariadb-java-client@3.5.1
3.5.9

Open the chart page →

1,710
keycloakkubelauncherVerified publisher0.4.41 of 1See more

keycloak kubelauncher 0.4.4

1 of the 1 container images this version deploys carry CVE-2026-55858.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/keycloakdigest-pinnedafe3bd73d7cf
mariadb-java-client@3.5.7
3.5.9

Open the chart page →

1,251
metabasedeliveryheroVerified publisher0.14.41 of 1See more

metabase deliveryhero 0.14.4

1 of the 1 container images this version deploys carry CVE-2026-55858.

Container imageDigestPackageFixed in
metabase/metabase:v0.45.21fb334ce4820
mariadb-java-client@2.7.6
2.7.14

Open the chart page →

2,572
zipkinygqygq2Verified publisher2.1.41 of 4See more

zipkin ygqygq2 2.1.4

1 of the 4 container images this version deploys carry CVE-2026-55858.

Container imageDigestPackageFixed in
openzipkin/zipkin:2.24197a9692f6a9
mariadb-java-client@2.7.11
2.7.14

Open the chart page →

2,764
musicocielmusicocielVerified publisher0.0.01 of 3See more

musicociel musicociel 0.0.0

1 of the 3 container images this version deploys carry CVE-2026-55858.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:23.0.34f72a5b0c076
mariadb-java-client@3.1.4
3.3.5

Open the chart page →

4,406
reposilitevolker-raschekVerified publisher1.0.01 of 1See more

reposilite volker-raschek 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-55858.

Container imageDigestPackageFixed in
dzikoysk/reposilite:3.5.264128c2d7a6ba
mariadb-java-client@3.5.6
3.5.9

Open the chart page →

2,957
convertigoconvertigoOfficialVerified publisher8.4.31 of 5See more

convertigo convertigo 8.4.3

1 of the 5 container images this version deploys carry CVE-2026-55858.

Container imageDigestPackageFixed in
library/convertigo:8.4.3ae605bfcda05
mariadb-java-client@3.5.8
3.5.9

Open the chart page →

17,404
cosmocosmo-platformOfficialVerified publisher0.20.01 of 10See more

cosmo cosmo-platform 0.20.0

1 of the 10 container images this version deploys carry CVE-2026-55858.

Container imageDigestPackageFixed in
ghcr.io/wundergraph/cosmo/keycloak:0.13.0b37408461b9b
mariadb-java-client@3.5.6
3.5.9

Open the chart page →

28,839
apimgraviteeioVerified publisher4.12.192 of 4See more

apim graviteeio 4.12.19

2 of the 4 container images this version deploys carry CVE-2026-55858.

Container imageDigestPackageFixed in
graviteeio/apim-gateway:4.12.19-debian05fd67a93056
mariadb-java-client@3.5.6
3.5.9
graviteeio/apim-management-api:4.12.19-debian27374522cd04
mariadb-java-client@3.5.6
3.5.9

Open the chart page →

4,806
egagenteginnovationsVerified publisher0.10.01 of 1See more

egagent eginnovations 0.10.0

1 of the 1 container images this version deploys carry CVE-2026-55858.

Container imageDigestPackageFixed in
eginnovations/agent:7.5.4e4dfe242fe9f
mariadb-java-client@3.5.7
3.5.9

Open the chart page →

1,340
featurehubfeaturehub4.1.61 of 7See more

featurehub featurehub 4.1.6

1 of the 7 container images this version deploys carry CVE-2026-55858.

Container imageDigestPackageFixed in
featurehub/mr:1.9.1477d8bf771a9
mariadb-java-client@2.7.10
2.7.14

Open the chart page →

8,240
traccarjeffrescVerified publisher0.2.01 of 2See more

traccar jeffresc 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-55858.

Container imageDigestPackageFixed in
traccar/traccar:6.7-alpine621c8d6d46fd
mariadb-java-client@3.5.3
3.5.9

Open the chart page →

1,341
linstorkvaps1.14.01 of 11See more

linstor kvaps 1.14.0

1 of the 11 container images this version deploys carry CVE-2026-55858.

Container imageDigestPackageFixed in
ghcr.io/kvaps/linstor-controller:v1.14.000ce11c31087
mariadb-java-client@2.6.0
2.7.14

Open the chart page →

15,547
metabasemetabase-helmVerified publisher2.7.11 of 1See more

metabase metabase-helm 2.7.1

1 of the 1 container images this version deploys carry CVE-2026-55858.

Container imageDigestPackageFixed in
metabase/metabase:v0.46.09ebdc664a6b2
mariadb-java-client@2.7.6
2.7.14

Open the chart page →

2,221
clowder2ncsaVerified publisher1.9.71 of 12See more

clowder2 ncsa 1.9.7

1 of the 12 container images this version deploys carry CVE-2026-55858.

Container imageDigestPackageFixed in
bitnamilegacy/keycloak:20.0.5cb04e49e6eb1
mariadb-java-client@3.0.8
3.3.5

Open the chart page →

37,373
portraitportraitVerified publisher0.2.131 of 8See more

portrait portrait 0.2.13

1 of the 8 container images this version deploys carry CVE-2026-55858.

Container imageDigestPackageFixed in
treskon/portrait:DEV-latest88e813f22347
mariadb-java-client@3.1.2
3.3.5

Open the chart page →

31,844
querysiakhooiVerified publisher1.0.01 of 1See more

query siakhooi 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-55858.

Container imageDigestPackageFixed in
siakhooi/query:1.0.0f1f4b5b1b870
mariadb-java-client@3.5.8
3.5.9

Open the chart page →

1,792
signserver-cesignserverOfficialVerified publisher2.3.51 of 1See more

signserver-ce signserver 2.3.5

1 of the 1 container images this version deploys carry CVE-2026-55858.

Container imageDigestPackageFixed in
keyfactor/signserver-ce:7.3.2798fbbe00283
mariadb-java-client@3.5.3
3.5.9

Open the chart page →

2,406
keycloakaccount-serviceVerified publisher18.4.51 of 2See more

keycloak account-service 18.4.5

1 of the 2 container images this version deploys carry CVE-2026-55858.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
mariadb-java-client@2.5.4
2.7.14

Open the chart page →

7,713
airbyteairbyte-v2Verified publisher2.2.01 of 10See more

airbyte airbyte-v2 2.2.0

1 of the 10 container images this version deploys carry CVE-2026-55858.

Container imageDigestPackageFixed in
airbyte/server:2.2.070e125498a1c
mariadb-java-client@3.5.6
3.5.9

Open the chart page →

12,473
airsonic-advancedairsonic-advancedVerified publisher0.3.11 of 1See more

airsonic-advanced airsonic-advanced 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-55858.

Container imageDigestPackageFixed in
linuxserver/airsonic-advanced:11.1.4d286a7f55a59
mariadb-java-client@3.3.2
3.3.5

Open the chart page →

1,748
pagesalstom-pages-app1.0.01 of 3See more

pages alstom-pages-app 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-55858.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
mariadb-java-client@2.6.0
2.7.14

Open the chart page →

20,190
pagesandrei-pages1.0.01 of 3See more

pages andrei-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-55858.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
mariadb-java-client@2.6.0
2.7.14

Open the chart page →

20,190
arlas-aiasarlas-stackVerified publisher28.8.01 of 22See more

arlas-aias arlas-stack 28.8.0

1 of the 22 container images this version deploys carry CVE-2026-55858.

Container imageDigestPackageFixed in
bitnamilegacy/keycloak:26.3.3-debian-12-r0da3df0976a9f
mariadb-java-client@3.5.3
3.5.9

Open the chart page →

40,238
idmassist-iot-identity-manager0.1.01 of 2See more

idm assist-iot-identity-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-55858.

Container imageDigestPackageFixed in
assistiot/identity-manager_kc:latest0df4b4fa899a
mariadb-java-client@2.5.4
2.7.14

Open the chart page →

13,352
axelor-open-suiteaxelor-open-suiteVerified publisher7.2.581 of 2See more

axelor-open-suite axelor-open-suite 7.2.58

1 of the 2 container images this version deploys carry CVE-2026-55858.

Container imageDigestPackageFixed in
pmoscode/axelor-open-suite:v7.2.57a58f4d762f5c
mariadb-java-client@2.7.10
2.7.14

Open the chart page →

9,722
keycloakbarravarVerified publisher1.0.41 of 1See more

keycloak barravar 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-55858.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:24.0.34d6f22991266
mariadb-java-client@3.3.3
3.3.5

Open the chart page →

2,381
pagesberrutig-pages1.0.01 of 3See more

pages berrutig-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-55858.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
mariadb-java-client@2.6.0
2.7.14

Open the chart page →

20,190
bluerange-serverbluerangeOfficialVerified publisher1.3.11 of 1See more

bluerange-server bluerange 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-55858.

Container imageDigestPackageFixed in
bluerange/bluerange:26.1.307c8f73b55df
mariadb-java-client@3.4.2
3.4.3

Open the chart page →

1,816
pagesbrian-pages1.0.01 of 3See more

pages brian-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-55858.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
mariadb-java-client@2.6.0
2.7.14

Open the chart page →

20,190
pagesbrixton-mayuribhavsar23-pages1.0.01 of 3See more

pages brixton-mayuribhavsar23-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-55858.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
mariadb-java-client@2.6.0
2.7.14

Open the chart page →

20,190
pagesbrixton-pages1.0.01 of 3See more

pages brixton-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-55858.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
mariadb-java-client@2.6.0
2.7.14

Open the chart page →

20,190
pagescamden-pages1.0.01 of 3See more

pages camden-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-55858.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
mariadb-java-client@2.6.0
2.7.14

Open the chart page →

20,190
pagescarina-pages1.0.01 of 3See more

pages carina-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-55858.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
mariadb-java-client@2.6.0
2.7.14

Open the chart page →

20,190
pagescarmel-pages-dell1.0.01 of 3See more

pages carmel-pages-dell 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-55858.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
mariadb-java-client@2.6.0
2.7.14

Open the chart page →

20,190
metabasecasemark2.16.111 of 1See more

metabase casemark 2.16.11

1 of the 1 container images this version deploys carry CVE-2026-55858.

Container imageDigestPackageFixed in
cmosborn/metabase-arm64:0.50.286ec0a8878ad2
mariadb-java-client@2.7.10
2.7.14

Open the chart page →

1,215
rundeckcloudnativeapp0.1.01 of 2See more

rundeck cloudnativeapp 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-55858.

Container imageDigestPackageFixed in
rundeck/rundeck:3.0.16b13e8059ad72
mariadb-java-client@1.7.4
2.7.14

Open the chart page →

23,665
pagescrypticcode-helmchart1.0.01 of 3See more

pages crypticcode-helmchart 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-55858.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
mariadb-java-client@2.6.0
2.7.14

Open the chart page →

20,190
pagesdalston-pages1.0.01 of 3See more

pages dalston-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-55858.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
mariadb-java-client@2.6.0
2.7.14

Open the chart page →

20,190
pagesdaman-dell-kuber1.0.01 of 3See more

pages daman-dell-kuber 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-55858.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
mariadb-java-client@2.6.0
2.7.14

Open the chart page →

20,190
damap-chartdamapVerified publisher0.3.01 of 5See more

damap-chart damap 0.3.0

1 of the 5 container images this version deploys carry CVE-2026-55858.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.49409c59bdfb6
mariadb-java-client@3.5.6
3.5.9

Open the chart page →

13,936
metabasedasmeta0.1.01 of 1See more

metabase dasmeta 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-55858.

Container imageDigestPackageFixed in
metabase/metabase:v0.63.1.124f150effd484
mariadb-java-client@2.7.10
2.7.14

Open the chart page →

804
pagesdavid-pages1.0.01 of 3See more

pages david-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-55858.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
mariadb-java-client@2.6.0
2.7.14

Open the chart page →

20,190
pagesdebasish-pages1.0.01 of 3See more

pages debasish-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-55858.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
mariadb-java-client@2.6.0
2.7.14

Open the chart page →

20,190
pagesdipak1.0.01 of 3See more

pages dipak 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-55858.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
mariadb-java-client@2.6.0
2.7.14

Open the chart page →

20,190

Container images carrying it

75 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
flyway/flyway:6.4.422d97ceb0c47
mariadb-java-client@2.6.0
2.7.14
79
apache/fineract:1.12.1a83cf1980609
mariadb-java-client@3.5.2
3.5.9
2
graviteeio/apim-gateway:4.12.19-debian05fd67a93056
mariadb-java-client@3.5.6
3.5.9
2
graviteeio/apim-management-api:4.12.19-debian27374522cd04
mariadb-java-client@3.5.6
3.5.9
2
metabase/metabase:v0.45.21fb334ce4820
mariadb-java-client@2.7.6
2.7.14
2
metabase/metabase:v0.61.1.x9491ed11c901
mariadb-java-client@2.7.10
2.7.14
2
ghcr.io/openunison/openunison-kubernetes-operator:1.0.11f4feb3323a29
mariadb-java-client@3.5.8
3.5.9
2
quay.io/keycloak/keycloak:26.1.4044a457e0498
mariadb-java-client@3.4.1
3.4.3
2
quay.io/keycloak/keycloak:20.0054ef67eb7da
mariadb-java-client@3.0.8
3.3.5
2
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
mariadb-java-client@2.5.4
2.7.14
2
1dev/server:11.9.0cd5b12fe5471
mariadb-java-client@2.3.0
2.7.14
1
airbyte/server:2.2.070e125498a1c
mariadb-java-client@3.5.6
3.5.9
1
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
mariadb-java-client@2.7.3
2.7.14
1
assistiot/identity-manager_kc:latest0df4b4fa899a
mariadb-java-client@2.5.4
2.7.14
1
bitnamilegacy/keycloak:20.0.5cb04e49e6eb1
mariadb-java-client@3.0.8
3.3.5
1
bitnamilegacy/keycloak:24.0.4cc599cbd15ff
mariadb-java-client@3.3.3
3.3.5
1
bitnamilegacy/keycloak:26.3.3-debian-12-r0da3df0976a9f
mariadb-java-client@3.5.3
3.5.9
1
bluerange/bluerange:26.1.307c8f73b55df
mariadb-java-client@3.4.2
3.4.3
1
cmosborn/metabase-arm64:0.50.286ec0a8878ad2
mariadb-java-client@2.7.10
2.7.14
1
dbeaver/cloudbeaver:26.1.287ab86d00f8c
mariadb-java-client@3.5.1
3.5.9
1
dremio/dremio-oss:24.1.080ed2e3b7c43
mariadb-java-client@3.0.8
3.3.5
1
dzikoysk/reposilite:3.5.264128c2d7a6ba
mariadb-java-client@3.5.6
3.5.9
1
easypi/openrefine:3.7.0d2950a36a576
mariadb-java-client@3.0.8
3.3.5
1
eginnovations/agent:7.5.4e4dfe242fe9f
mariadb-java-client@3.5.7
3.5.9
1
eikek0/sharry:1.8.0661ff3ef42cd
mariadb-java-client@2.7.3
2.7.14
1
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
mariadb-java-client@3.4.1
3.4.3
1
featurehub/mr:1.9.1477d8bf771a9
mariadb-java-client@2.7.10
2.7.14
1
flyway/flyway:9.1545b5d7cdc75a
mariadb-java-client@2.7.2
2.7.14
1
flyway/flyway:9.14.1-alpine80f12c80502b
mariadb-java-client@2.7.2
2.7.14
1
keyfactor/signserver-ce:7.3.2798fbbe00283
mariadb-java-client@3.5.3
3.5.9
1
kvalitetsit/stakit-backend:0.3.0f0af0ba589af
mariadb-java-client@3.3.3
3.3.5
1
library/convertigo:8.4.3ae605bfcda05
mariadb-java-client@3.5.8
3.5.9
1
linuxserver/airsonic-advanced:11.1.4d286a7f55a59
mariadb-java-client@3.3.2
3.3.5
1
ma1uta/ma1sd:2.5.0ee2a56d8b8ca
mariadb-java-client@2.7.2
2.7.14
1
metabase/metabase:v0.63.1.124f150effd484
mariadb-java-client@2.7.10
2.7.14
1
metabase/metabase:v0.53.4.17807bc5cad17
mariadb-java-client@2.7.10
2.7.14
1
metabase/metabase:v0.46.09ebdc664a6b2
mariadb-java-client@2.7.6
2.7.14
1
openkm/openkm-ce:6.3.113bc465a7461b
mariadb-java-client@2.2.5
2.7.14
1
openzipkin/zipkin:2.24197a9692f6a9
mariadb-java-client@2.7.11
2.7.14
1
openzipkin/zipkin:2.21.060c3970df479
mariadb-java-client@2.6.0
2.7.14
1
openzipkin/zipkin-gcp:0.15.2b5d51d1144e2
mariadb-java-client@2.5.1
2.7.14
1
pmoscode/axelor-open-suite:v7.2.57a58f4d762f5c
mariadb-java-client@2.7.10
2.7.14
1
rrobetti/ojp:0.1.0-beta1141bd88232b
mariadb-java-client@3.5.2
3.5.9
1
rundeck/rundeck:3.2.74d64fe56f767
mariadb-java-client@1.7.4
2.7.14
1
rundeck/rundeck:3.0.16b13e8059ad72
mariadb-java-client@1.7.4
2.7.14
1
siakhooi/query:1.0.0f1f4b5b1b870
mariadb-java-client@3.5.8
3.5.9
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
mariadb-java-client@2.7.0
2.7.14
1
traccar/traccar:6.7-alpine621c8d6d46fd
mariadb-java-client@3.5.3
3.5.9
1
treskon/portrait:DEV-latest88e813f22347
mariadb-java-client@3.1.2
3.3.5
1
trinodb/trino:4801565e8cac299
mariadb-java-client@3.3.4
3.3.5
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.